Latest pimcore pimcore Vulnerabilities

Pimcore missing token/header to prevent CSRF
Pimcore Pimcore<4.0.5
SQL Injection in Admin Grid Filter API in Pimcore
composer/pimcore/pimcore<11.1.1
Pimcore Pimcore<11.1.1
Cross-site Scripting (XSS) - Stored in pimcore/pimcore
Pimcore Pimcore<11.1.0
composer/pimcore/pimcore<11.1.0
Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.8.
Pimcore Pimcore<10.6.8
composer/pimcore/pimcore<10.6.8
Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. A path traversal vulnerability exists in the `AssetController::importServerFilesAction`...
composer/pimcore/pimcore<10.6.7
Pimcore Pimcore<10.6.7
SQL Injection in GitHub repository pimcore/pimcore prior to 10.6.4.
Pimcore Pimcore<10.6.4
composer/pimcore/pimcore<10.6.4
### Impact Unauthorized users are able to obtain sensitive information about the system's runtime environment, features they have no permissions to access, etc. ### Patches Update to version 10.6.4 o...
Pimcore Pimcore<10.6.4
composer/pimcore/pimcore<10.6.4
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.6.4.
Pimcore Pimcore<10.6.4
Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.4.
Pimcore Pimcore<10.6.4
SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.24.
Pimcore Pimcore<10.5.24
composer/pimcore/pimcore<10.5.24
Privilege Defined With Unsafe Actions in GitHub repository pimcore/pimcore prior to 10.5.23.
Pimcore Pimcore<10.5.23
Path Traversal: '\..\filename' in GitHub repository pimcore/pimcore prior to 10.5.22.
Pimcore Pimcore<10.5.22
Microsoft Windows
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3.
Pimcore Pimcore<10.3.3
composer/pimcore/pimcore<10.3.3
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.
Pimcore Pimcore<10.5.21
composer/pimcore/pimcore<10.5.21
Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21.
Pimcore Pimcore<10.5.21
Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.21.
Pimcore Pimcore<10.5.21
Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21.
Pimcore Pimcore<10.5.21
Pimcore is an open source data and experience management platform. Versions of Pimcore prior to 10.5.18 are vulnerable to path traversal. The impact of this path traversal and arbitrary extension is l...
Pimcore Pimcore<10.5.18
composer/pimcore/pimcore<10.5.18
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.
Pimcore Pimcore<10.5.21
composer/pimcore/pimcore<10.5.21
Pimcore is an open source data and experience management platform. Prior to version 10.5.21, the `/admin/misc/script-proxy` API endpoint that is accessible by an authenticated administrator user is vu...
Pimcore Pimcore<10.5.21
composer/pimcore/pimcore<10.5.21
Pimcore is an open source data and experience management platform. Prior to version 10.5.21, a SQL Injection vulnerability exists in the admin translations API. Users should update to version 10.5.21 ...
Pimcore Pimcore<10.5.21
composer/pimcore/pimcore<10.5.21
Pimcore is an open source data and experience management platform. Prior to version 10.5.21, A SQL injection vulnerability exists in the translation export API. Users should update to version 10.5.21 ...
Pimcore Pimcore<10.5.21
composer/pimcore/pimcore<10.5.21
Pimcore is an open source data and experience management platform. Prior to version 10.5.21, the admin search find API has a SQL injection vulnerability. Users should upgrade to version 10.5.21 to rec...
Pimcore Pimcore<10.5.21
composer/pimcore/pimcore<10.5.21
Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.21.
Pimcore Pimcore<10.5.21
### Impact Malicious JavaScript has access to all the same objects as the rest of the web page, including access to cookies and local storage, which are often used to store session tokens. If an attac...
composer/pimcore/pimcore<10.5.21
Pimcore Pimcore<10.5.21
Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21.
composer/pimcore/pimcore<10.5.21
Pimcore Pimcore<10.5.21
### Impact The attacker is capable to stolen the user session cookie. it will leads to complete account takeover. ### Patches Update to version 10.5.21 or apply this patch manually https://github.com...
composer/pimcore/pimcore<10.5.21
Pimcore Pimcore<10.5.21
### Impact Stored cross site scripting vulnerability in operator any getter in dataobject grid configuration. ### Patches Update to version 10.5.21 or apply this patch manually https://github.com/pim...
Pimcore Pimcore<10.5.21
### Impact SQL injections in AssetController due to unsanitized concatenating strings in where clause. The attacker can dump database, alter data or perform dos on the backend database. ### Patches U...
composer/pimcore/pimcore<10.5.21
Pimcore Pimcore<10.5.21
Path Traversal in GitHub repository pimcore/pimcore prior to 10.5.21.
Pimcore Pimcore<10.5.21
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.
Pimcore Pimcore<10.5.21
composer/pimcore/pimcore<10.5.21
Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21.
Pimcore Pimcore<10.5.21
composer/pimcore/pimcore<10.5.21
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.
Pimcore Pimcore<10.5.21
composer/pimcore/pimcore<10.5.21
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.
Pimcore Pimcore<10.5.21
composer/pimcore/pimcore<10.5.21
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.20.
Pimcore Pimcore<10.5.20
Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.20.
Pimcore Pimcore<10.5.20
Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.20.
Pimcore Pimcore<10.5.20
Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.20.
Pimcore Pimcore<10.5.20
Pimcore is an open source data and experience management platform. Prior to version 10.5.19, since a user with 'report' permission can already write arbitrary SQL queries and given the fact that this ...
Pimcore Pimcore<10.5.19
SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.19.
Pimcore Pimcore<10.5.19
Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.19.
Pimcore Pimcore<10.5.19
Pimcore is an open source data and experience management platform. Versions prior to 10.5.19 have an unsecured tooltip field in DataObject class definition. This vulnerability has the potential to ste...
Pimcore Pimcore<10.5.19
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.19.
Pimcore Pimcore<10.5.19
Pimcore is an open source data and experience management platform. Prior to version 10.5.19, quoting is not done properly in UUID DAO model. There is the theoretical possibility to inject custom SQL i...
Pimcore Pimcore<10.5.19
Pimcore is an open source data and experience management platform. Prior to version 10.5.19, an attacker can use cross-site scripting to send a malicious script to an unsuspecting user. Users may upgr...
Pimcore Pimcore<10.5.19
Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.19.
Pimcore Pimcore<10.5.19
Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.19.
Pimcore Pimcore<10.5.19
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.19.
Pimcore Pimcore<10.5.19
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.18.
Pimcore Pimcore<10.5.18
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.18.
Pimcore Pimcore<10.5.18

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203